Also known as: APT28, Fancy Bear, GalaxyGato, Nimbus Manticore, aerospace, telecommunications, tracked as, Tunisian, Earth Bluecrow, DecisiveArchitect, Red Dev 18, the Newscaster Team, Tunisian Maskers Cyber Force, Subtle Snail, focused on defense, government entities, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, Pawn Storm, MiniDionis, Chinastrats, 2026, Altoufan Team, regional government enti, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, Haywire Kitten
Conquerors Electronic Army operates under the “Wa’d al‑Akhira” banner and claims responsibility for a range of disruptive operations, including mass DDoS blasts against Israeli civil and defense entities, and sabotage of critical infrastructure in the Middle East. Their tactics combine high‑volume traffic floods with credential harvesting via malicious mobile applications, as well as targeted wiper malware designed to incapacitate industrial control systems. The group’s attacks are often coordinated across multiple platforms – from rented stressers for volumetric pressure to exploit kits that deliver malicious APKs for phishing and exfiltration. Reports attribute a 149‑attack wave in early March 2026 to CEA and allied pro‑Russian or pro‑Iranian actors, illustrating an operational tempo capable of influencing national security infrastructure. CEA does not seek only disruption; there are indications of influence operations, as evidenced by defacement (T1491) and the embedding of links to a UK‑registered charity during campaigns. Their multi‑faceted approach demonstrates both opportunistic and ideologically driven motives, targeting sectors that provide strategic leverage over regional politics.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Conquerors Electronic Army (CEA) is a hybrid, pro‑regional threat actor that blends disruptive denial‑of‑service campaigns with sabotage against industrial control systems and credential‑exfiltration efforts. They target government, defense, financial, and critical‑infrastructure sectors across the Middle East, Israel, Russia, Iran, and neighboring nations, using volumetric DDoS attacks to disrupt services while deploying wiper malware and phishing through mobile apps to gain long‑term footholds.
Goals & Targeting
CEA’s strategic objectives blend political advocacy with cyber sabotage aimed at weakening rival state capabilities. By attacking high‑visibility government and defense entities – including SCADA facilities, military communications, and financial institutions – they aim to create instability and showcase technological superiority for their perceived supporters. Their use of social engineering via mobile apps suggests an effort to sow mistrust and acquire credentials that could be leveraged in future influence campaigns. The actor’s focus on the Middle East indicates a clear geopolitical agenda tied to regional power dynamics involving Iran, Russia, and Israel.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CEA’s campaigns illustrate a recurring pattern of synchronized, multi‑vector assaults that target both the service layer and control infrastructure. In March 2026 they launched 149 volumetric DDoS attacks across 16 countries, simultaneously distributing phishing through malware‑laden mobile apps and deploying wiper payloads to industrial networks. The actor’s operations are generally rapid yet coordinated, indicating a well‑structured threat group capable of leveraging rented stresser services for large‑scale disruption while maintaining stealthy credential exfiltration channels. Their choice of victims—government agencies, defense contractors, energy utilities, and financial institutions—underscores an intent to cripple critical national assets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level is moderate, based on reports from Rescana and Radware that identify Conquerors Electronic Army in coordinated campaigns and attribute specific tactics. However, concrete attribution remains challenging due to reliance on single‑source analyses, evolving alias usage, and lack of publicly detailed technical signatures for all observed attacks. Gaps persist regarding precise timelines, motive clarity beyond disruptive intent, and the full extent of their toolset.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
43
Tools
0
Campaigns
20
IOCs
0
Observed Data
6
Tactics